# Conflicts: # .agents/notes/implemented/feature/2026-07-14-cross-family-fs-sandbox.i18n.yaml # .agents/notes/implemented/feature/2026-07-14-cross-family-fs-sandbox.md # .agents/notes/implemented/feature/2026-07-14-cross-family-fs-sandbox.zh.md # docs/capability-seams.md # docs/cordis-catalog/events.md # docs/cordis-catalog/services.md # docs/event-producer-consumer.md # docs/module-graph.md # docs/persistence-catalog.md # docs/rfc/INDEX.md # examples/acp-agent/README.md # examples/acp-agent/fs.cordis.snapshot.yml # examples/acp-agent/fs.cordis.yml # examples/acp-agent/tests/snapshots/escalation-approved/session.jsonl # examples/acp-agent/tests/snapshots/escalation-rejected/session.jsonl # examples/acp-agent/tests/snapshots/hook-cc-pretool-ask/session.jsonl # examples/acp-agent/tests/snapshots/permission-switching/session.jsonl # examples/acp-agent/tests/snapshots/workspace-context/system-prompt.expected.md # examples/acp-agent/tests/snapshots/workspace-context/tool-schemas.expected.json # examples/acp-agent/tests/snapshots/workspace-edit/system-prompt.expected.md # examples/acp-agent/tests/snapshots/workspace-edit/tool-schemas.expected.json # packages/bash/bash/src/index.ts # packages/bash/tool-bash/package.json # packages/bash/tool-bash/src/index.ts # packages/bash/tool-bash/tests/tools.spec.ts # packages/cordis/tool-cordis/src/api-catalog.ts # packages/fs/README.md # packages/fs/tool-fs/src/edit.ts # packages/fs/tool-fs/src/write.ts # packages/sandbox/README.md # pnpm-lock.yaml
36 lines
1.9 KiB
Markdown
36 lines
1.9 KiB
Markdown
<!-- Generated by scripts/gen-website-api.ts — do not edit by hand. Run `pnpm run gen-website-api` to regenerate. -->
|
|
|
|
# ctx.sandbox
|
|
|
|
`SandboxProvider` (abstract seam) — provided by `@deepseek-ai/dsh-sandbox`.
|
|
|
|
Abstract process-sandbox service. confine must return enforcing argv or fail closed at wrap or runner-execution time; silent unconfined passthrough is forbidden. Functional probes arbitrate multi-runner chains and may be skipped for a sole candidate, whose own refusal remains the fail-closed end.
|
|
|
|
[Source](https://github.com/deepseek-harness/deepseek-harness/blob/master/packages/sandbox/sandbox/src/index.ts#L122)
|
|
|
|
### ctx.sandbox.confine(argv, policy)
|
|
|
|
```ts website-api
|
|
/**
|
|
* Wrap `argv` so it executes confined under `policy` on this host; the
|
|
* caller spawns the returned argv in place of its own.
|
|
* @param argv - the exact argv the caller is about to spawn (program plus
|
|
* arguments), NOT a shell string — a shell-shaped consumer passes
|
|
* `['bash', '-c', command]`.
|
|
* @param policy - the file-effect policy this execution runs under,
|
|
* carried per call (see {@link SandboxPolicy}).
|
|
* @returns the argv to spawn instead, plus the enforcement completeness
|
|
* the selected backend achieves for it.
|
|
*/
|
|
abstract confine(argv: readonly string[], policy: SandboxPolicy): ConfinedArgv
|
|
```
|
|
|
|
Wrap `argv` so it executes confined under `policy` on this host; the caller spawns the returned argv in place of its own.
|
|
|
|
- `argv` — the exact argv the caller is about to spawn (program plus arguments), NOT a shell string — a shell-shaped consumer passes `['bash', '-c', command]`.
|
|
- `policy` — the file-effect policy this execution runs under, carried per call (see `SandboxPolicy`).
|
|
|
|
**Returns** the argv to spawn instead, plus the enforcement completeness the selected backend achieves for it.
|
|
|
|
[Source](https://github.com/deepseek-harness/deepseek-harness/blob/master/packages/sandbox/sandbox/src/index.ts#L138)
|